🇺🇸
TPI-Abuse
2026-09-04 13:29:46
(34 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.17.111.41 (41.111.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.111.41 (41.111.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:29:40.766000 2026] [security2:error] [pid 32251:tid 32251] [client 34.17.111.41:38736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.adamsclothiers.com"] [uri "/.git/config"] [unique_id "aprHxCdxqdLfEMXhr62Y_AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:56:29
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.17.111.41 (41.111.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.111.41 (41.111.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:56:21.946761 2026] [security2:error] [pid 6216:tid 6216] [client 34.17.111.41:56180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.acmax.com"] [uri "/.git/config"] [unique_id "apq_9akLhl86-eaf1O8f9AAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:45:05
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.111.41 (41.111.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.111.41 (41.111.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:44:59.251857 2026] [security2:error] [pid 14986:tid 14986] [client 34.17.111.41:40994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.abdulhameeds.art"] [uri "/.git/config"] [unique_id "apqvO-QFkUuS9MPugK_boAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-04 09:00:05
(5 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 08:48:05
(5 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-03 17:03:09
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.111.41 (41.111.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.111.41 (41.111.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 13:03:03.939400 2026] [security2:error] [pid 27818:tid 27818] [client 34.17.111.41:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.wiszen.org"] [uri "/.git/config"] [unique_id "apmoRxxbd482jLtuQAPp3wAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 11:58:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.17.111.41 (41.111.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.111.41 (41.111.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 07:58:05.288126 2026] [security2:error] [pid 3011:tid 3011] [client 34.17.111.41:44490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.wa211.org"] [uri "/.git/config"] [unique_id "aplgzUdPVAI_wkq4bCOxMwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-09-03 06:40:49
(1 day ago)
[ThuSep0308:40:43.1235422026][security2:error][pid2526038:tid2526129][client34.17.111.41:0]ModSecuri ...
show more
[ThuSep0308:40:43.1235422026][security2:error][pid2526038:tid2526129][client34.17.111.41:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpcalendars.vg13.ch\"][uri\"/.env.bak\"][unique_id\"apkWa5nr1_xzO2nzJa7JYQAAAMQ\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 04:22:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.17.111.41 (41.111.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.111.41 (41.111.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 00:22:36.643231 2026] [security2:error] [pid 26881:tid 26881] [client 34.17.111.41:38046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.avaliantlife.com"] [uri "/.git/config"] [unique_id "apj2DOUQ0xau20L1HZoBNAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 01:10:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.17.111.41 (41.111.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.111.41 (41.111.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 21:10:27.820503 2026] [security2:error] [pid 19953:tid 19953] [client 34.17.111.41:59278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.unwaved.com"] [uri "/.git/config"] [unique_id "apjJAxxYVNg5sfo1o5QqawAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Apache
2026-09-02 22:21:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.17.111.41 (IT/Italy/41.111.17.34.bc.googleus ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.111.41 (IT/Italy/41.111.17.34.bc.googleusercontent.com): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 20:13:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.17.111.41 (41.111.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.111.41 (41.111.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 16:13:34.521576 2026] [security2:error] [pid 23650:tid 23650] [client 34.17.111.41:41926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.angove.biz"] [uri "/.git/config"] [unique_id "apiDbl8mExTG1Y9_RUh4ZQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-02 19:50:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇿🇦
conure.sh
2026-09-02 19:23:18
(1 day ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 1s
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-02 19:16:14
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.17.111.41 (IT/Italy/41.111.17.34.bc.googleus ...
show more
(mod_security) mod_security (id:949110) triggered by 34.17.111.41 (IT/Italy/41.111.17.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack